Skip to Content
Odoo Menu
  • Log ind
  • Prøv gratis
  • Apps
    Økonomi
    • Bogføring
    • Fakturering
    • Udgifter
    • Regneark (BI)
    • Dokumenter
    • e-Signatur
    Salg
    • CRM
    • Salg
    • POS Butik
    • POS Restaurant
    • Abonnementer
    • Udlejning
    Hjemmeside
    • Hjemmesidebygger
    • e-Handel
    • Blog
    • Forum
    • LiveChat
    • e-Læring
    Forsyningskæde
    • Lagerbeholdning
    • Produktion
    • PLM
    • Indkøb
    • Vedligeholdelse
    • Kvalitet
    HR
    • Medarbejdere
    • Rekruttering
    • Fravær
    • Medarbejdersamtaler
    • Anbefalinger
    • Flåde
    Marketing
    • Markedsføring på sociale medier
    • E-mailmarketing
    • SMS-marketing
    • Arrangementer
    • Automatiseret marketing
    • Spørgeundersøgelser
    Tjenester
    • Projekt
    • Timesedler
    • Udkørende Service
    • Kundeservice
    • Planlægning
    • Aftaler
    Produktivitet
    • Dialog
    • Godkendelser
    • IoT
    • VoIP
    • Vidensdeling
    • WhatsApp
    Tredjepartsapps Odoo Studio Odoo Cloud-platform
  • Brancher
    Detailhandel
    • Boghandel
    • Tøjforretning
    • Møbelforretning
    • Dagligvarebutik
    • Byggemarked
    • Legetøjsforretning
    Mad og værtsskab
    • Bar og pub
    • Restaurant
    • Fastfood
    • Gæstehus
    • Drikkevareforhandler
    • Hotel
    Ejendom
    • Ejendomsmægler
    • Arkitektfirma
    • Byggeri
    • Ejendomsadministration
    • Havearbejde
    • Boligejerforening
    Rådgivning
    • Regnskabsfirma
    • Odoo-partner
    • Marketingbureau
    • Advokatfirma
    • Rekruttering
    • Audit & certificering
    Produktion
    • Tekstil
    • Metal
    • Møbler
    • Fødevareproduktion
    • Bryggeri
    • Firmagave
    Heldbred & Fitness
    • Sportsklub
    • Optiker
    • Fitnesscenter
    • Kosmetolog
    • Apotek
    • Frisør
    Håndværk
    • Handyman
    • IT-hardware og support
    • Solenergisystemer
    • Skomager
    • Rengøringsservicer
    • VVS- og ventilationsservice
    Andet
    • Nonprofitorganisation
    • Miljøagentur
    • Udlejning af billboards
    • Fotografi
    • Cykeludlejning
    • Softwareforhandler
    Gennemse alle brancher
  • Community
    Få mere at vide
    • Tutorials
    • Dokumentation
    • Certificeringer
    • Oplæring
    • Blog
    • Podcast
    Bliv klogere
    • Udannelselsesprogram
    • Scale Up!-virksomhedsspillet
    • Besøg Odoo
    Få softwaren
    • Download
    • Sammenlign versioner
    • Udgaver
    Samarbejde
    • Github
    • Forum
    • Arrangementer
    • Oversættelser
    • Bliv partner
    • Tjenester til partnere
    • Registrér dit regnskabsfirma
    Modtag tjenester
    • Find en partner
    • Find en bogholder
    • Kontakt en rådgiver
    • Implementeringstjenester
    • Kundereferencer
    • Support
    • Opgraderinger
    Github Youtube Twitter LinkedIn Instagram Facebook Spotify
    +1 (650) 691-3277
    Få en demo
  • Prissætning
  • Hjælp

Odoo is the world's easiest all-in-one management software.
It includes hundreds of business apps:

  • CRM
  • e-Commerce
  • Bogføring
  • Lager
  • PoS
  • Projekt
  • MRP
All apps
Du skal være registreret for at interagere med fællesskabet.
All Posts People Emblemer
Tags (View all)
odoo accounting v14 pos v15
Om dette forum
Du skal være registreret for at interagere med fællesskabet.
All Posts People Emblemer
Tags (View all)
odoo accounting v14 pos v15
Om dette forum
Hjælp

Why does OpenERP store passwords in plain text by default

Tilmeld

Få besked, når der er aktivitet på dette indlæg

Dette spørgsmål er blevet anmeldt
securityv7
4 Besvarelser
10465 Visninger
Avatar
IBS Group

I would like to hear some input from the Dev team.

4
Avatar
Kassér
Obay Albadri

Check this: http://help.openerp.com/question/6545/does-openerp-store-passwords-in-clear-text/

IBS Group
Forfatter

Yes I saw, my question is slightly different than that one :)

Obay Albadri

Yes it is, i am waiting for explanation too. :)

hiren

For me more crucially, why is communication using xmlrpc and not xmlrpcs by default? The nature of openerp is that it houses businesses core data, it should by nature think of security first. Users passwords are also not checked for complexity, users can happily use passwords123 in openerp, for business use, that's bad.

Avatar
Fabien Pinckaers (fp)
Bedste svar

The real reason is historical. We never thought "ok, it's a good idea to not encrypt password by default".

We implemented the plain password XML-RPC auth as it was the fastest implementation back in 2005, when our priority was to deliver our direct implementation customers asap. (and we didn't had extra budget at that time to implement several auth methods).

Since then, we have added encryption as a module "auth_crypt" as well as other authentification mechanisms; ldap, openid, oauth, etc. Every authentification mechanism is implemented by a specific module. We supplied them as optionnal modules so that everyone can choose the one he needs. We did not installed base_crypt by default as it's implementation was not compatible with ldap. (I do not know if it's still the case)

I guess we did not changed the default mode because: 1/ there is always something more important to do (the todo was trapped in the daily flow of things to do), 2/ it would have broken compatibilities for existing customers. 3/ base_crypt was not compatible with auth_ldap (but I think this should be fixed now)

Since the point 2 is not a problem anymore as we have a good migration service now, we should change the default the encrypted password in the next version.

Can anyone propose a merge proposal on the trunk branch to change the default?

7
Avatar
Kassér
IBS Group
Forfatter

Thank you for the thorough explanation.

Avatar
Brian Dunnette
Bedste svar

The OpenERP developers have justified the use of plain-text passwords as a password-recovery measure:

"As for the reason for cleartext passwords: once you switch to encrypted passwords you can't recover user passwords anymore. So enabling it is a choice, because there's no going back. We don't currently plan to make passwords encrypted by default."

(from OpenERP bug #738721)

1
Avatar
Kassér
Avatar
Gustavo
Bedste svar

I see the point in the question, IMHO as long as you protect the PostgreSQL database and root users, you are going to be fine from a security standpoint. It's not perfect, but I would enforce security at the server level instead of the appĺication level

1
Avatar
Kassér
Avatar
Francesco OpenCode
Bedste svar

If you want you can install module auth_crypt (standard OpenERP module) to crypt your passwords but, after this, you can't recovery them. You can choose!

0
Avatar
Kassér
Enjoying the discussion? Don't just read, join in!

Create an account today to enjoy exclusive features and engage with our awesome community!

Tilmeld dig
Related Posts Besvarelser Visninger Aktivitet
Creating user groups that allow users to access several companies
security v7
Avatar
Avatar
1
feb. 25
8778
Aps menu request access to apps.openerp.com
security v7
Avatar
Avatar
1
mar. 15
6641
Settings to session timeout? Løst
security v7 session
Avatar
Avatar
17
apr. 24
59576
Permission for a group to edit a single field only? Løst
security v7 groups
Avatar
Avatar
Avatar
Avatar
Avatar
10
dec. 23
38081
Why there is not timeout period - session/connection to expire in OpenERP? Løst
security v7 connection
Avatar
Avatar
2
jun. 20
26120
Community
  • Tutorials
  • Dokumentation
  • Forum
Open Source
  • Download
  • Github
  • Runbot
  • Oversættelser
Tjenester
  • Odoo.sh-hosting
  • Support
  • Opgradere
  • Individuelt tilpasset udvikling
  • Uddannelse
  • Find en bogholder
  • Find en partner
  • Bliv partner
Om os
  • Vores virksomhed
  • Brandaktiver
  • Kontakt os
  • Stillinger
  • Arrangementer
  • Podcast
  • Blog
  • Kunder
  • Juridiske dokumenter • Privatlivspolitik
  • Sikkerhedspolitik
الْعَرَبيّة Català 简体中文 繁體中文 (台灣) Čeština Dansk Nederlands English Suomi Français Deutsch हिंदी Bahasa Indonesia Italiano 日本語 한국어 (KR) Lietuvių kalba Język polski Português (BR) română русский язык Slovenský jazyk slovenščina Español (América Latina) Español ภาษาไทย Türkçe українська Tiếng Việt

Odoo er en samling open source-forretningsapps, der dækker alle dine virksomhedsbehov – lige fra CRM, e-handel og bogføring til lagerstyring, POS, projektledelse og meget mere.

Det unikke ved Odoo er, at systemet både er brugervenligt og fuldt integreret.

Website made with

Odoo Experience on YouTube

1. Use the live chat to ask your questions.
2. The operator answers within a few minutes.

Live support on Youtube
Watch now